cbcvebase.
CVE-2025-68321
published 2025-12-16

CVE-2025-68321: In the Linux kernel, the following vulnerability has been resolved: page_pool: always add GFP_NOWARN for ATOMIC allocations Driver authors often forget to add…

PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.39%
31.4th percentile
In the Linux kernel, the following vulnerability has been resolved: page_pool: always add GFP_NOWARN for ATOMIC allocations Driver authors often forget to add GFP_NOWARN for page allocation from the datapath. This is annoying to users as OOMs are a fact of life, and we pretty much expect network Rx to hit page allocation failures during OOM. Make page pool add GFP_NOWARN for ATOMIC allocations by default.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= ff7d6b27f894f1469dc51ccb828b7363ccd9799f < 0ec2cd5c58793d0c622797cd5fbe26634b3572100ec2cd5c58793d0c622797cd5fbe26634b357210
linuxlinux>= ff7d6b27f894f1469dc51ccb828b7363ccd9799f < 9835a0fd59a1df5ec0740fdab6d50db68e0f10de9835a0fd59a1df5ec0740fdab6d50db68e0f10de
linuxlinux>= ff7d6b27f894f1469dc51ccb828b7363ccd9799f < 7613c06ffa89c1e2266fb532e23ef7dfdf269d737613c06ffa89c1e2266fb532e23ef7dfdf269d73
linuxlinux>= ff7d6b27f894f1469dc51ccb828b7363ccd9799f < 3671a0775952026228ae44e096eb144bca75f8dc3671a0775952026228ae44e096eb144bca75f8dc
linuxlinux>= ff7d6b27f894f1469dc51ccb828b7363ccd9799f < ab48dc0e23eb714b3f233f8e8f6deed7df2051f5ab48dc0e23eb714b3f233f8e8f6deed7df2051f5
linuxlinux>= ff7d6b27f894f1469dc51ccb828b7363ccd9799f < f3b52167a0cb23b27414452fbc1278da2ee884fcf3b52167a0cb23b27414452fbc1278da2ee884fc
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.18.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
ubuntulinux-aws
ubuntulinux-azure-5.15
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.